Ahead of the International Airport Summit 2026, Carol-Ann Gaddis, Director of Information Technology and Innovation at Richmond International Airport explores the governance challenges airports must address now to ensure the frictionless journey is built on trust.

ChatGPT Image Sep 3, 2026, 09_15_17 AM

The frictionless airport journey has moved from concept to partial reality faster than expected. Today, a traveller departing major global hubs like Dubai, Singapore, or Amsterdam can move from curb to gate - check-in, bag drop, security, border control, lounge, and boarding - with no physical document presented, no boarding pass scanned, and no queue joined at a staffed desk. Their face serves as their ticket, passport, and key. The experience is genuinely transformative for those with access, yet that traveller remains the exception. Across the global network of roughly 1,200 commercial airports, the seamless biometric journey remains a flagship experiment concentrated in well-resourced hubs with favourable regulatory environments. Most airports and travellers still experience a journey defined by repeated document checks, disconnected systems, and staffing queues.

Why governance, not technology, is now the challenge

The gap between vision and reality is no longer a technology problem. The capability exists, with highly accurate facial recognition systems commercially available and mature international standards frameworks - such as ICAO’s Digital Travel Credential, IATA’s One ID, and the W3C Verifiable Credentials specification - already in place. What is missing is the governance architecture to deploy these systems responsibly, equitably, and at scale. In the airport context, digital identity means binding a traveller’s verified personal attributes into a single, portable, cryptographically secured representation that every stakeholder along the journey can trust. The next one to three years, running through 2028 and early 2029, represent the crucial window during which defaults for these systems will be set. Decisions made now will determine the architecture that governs traveller identity for the next decade.

Consent and the disappearing right to opt out

The first major challenge centres on consent architecture and the gradual erosion of meaningful opt-out mechanisms. Every biometric programme operating at a commercial airport is publicly described as voluntary, but voluntariness exists on a spectrum shaped by operational conditions. When a biometric lane processes travellers in three minutes while a document-based lane takes twenty-five, or when staffed alternatives are relocated to inconvenient areas and understaffed during peak hours, the choice becomes illusory. When traveller communication consists of hidden terms of service rather than plain-language explanations at enrolment, informed consent effectively disappears. As biometric corridors scale, airport operators face growing financial and operational pressure to reduce paper-based alternatives, eroding genuine opt-out options just as global regulators increase scrutiny under frameworks like the EU GDPR, the EU AI Act, and state-level privacy legislation like Illinois’ Biometric Information Privacy Act.

Addressing consent requires specific operational actions calibrated to airport size. A small hub handling under five million annual passengers typically operates few biometric touchpoints, often through airline contracts where the airport lacks direct oversight. Small hub leadership must immediately conduct contract reviews for every biometric touchpoint to clarify data retention, deletion request workflows, and template disposition after contract termination, while designating a dedicated staff member to oversee consent policy. Medium hubs handling five to twenty-five million passengers should publish a plain-language Biometric Use Policy before deploying new phases, clearly detailing data capture, retention timelines, and deletion procedures. They must also enforce documented service-level agreements for staffed fallback lanes - measuring maximum wait times and staffing levels - to ensure travellers who opt out are not penalised. Large hubs above 25 million passengers must audit their entire terminal estate across all third-party operators, mapping data flows and publishing summary findings to set industry compliance standards.

Data retention, secondary use and mission creep

The second governance theme involves data retention, secondary use, and mission creep. The core promise of a well-designed digital identity system is a clean, single transaction: a live biometric is compared against a reference image, a match result is returned, and the image is immediately discarded. However, biometric images and match results hold immense commercial and governmental value for building traveller behavioural profiles, training AI models, or sharing data across security agencies.

Mission creep rarely happens through a single dramatic decision; it occurs through accumulated small extensions, such as lengthening retention periods for operational convenience or including broad vendor data-sharing clauses. Left ungoverned, verification systems risk converting into persistent surveillance infrastructure, particularly as commercial pressure on non-aeronautical revenues and governmental appetite for movement data increase.

To mitigate secondary use risks, small hubs must audit all vendor contracts specifically for retention language and third-party data-sharing permissions, while maintaining a basic internal data flow register that documents what data is stored, where it resides, and who has access. Medium hubs should establish a cross-functional Data Governance Working Group involving legal, IT, operations, compliance, and border agencies to deliver a comprehensive data register and establish a formal Secondary Use Policy within 12 months.

They must also evaluate legal exposure regarding real-time biometric tracking rules under emerging regulatory frameworks. Large hubs must actively engage with international standards bodies like ICAO and IATA to shape data-retention guidelines, while conducting annual audits of all data-sharing agreements operating within their facilities to ensure third-party compliance does not compromise the airport’s legal standing.

When biometric accuracy becomes an equity issue

The third critical theme addresses algorithmic accuracy and demographic equity. Leading commercial facial recognition systems report controlled laboratory accuracy rates above 99.9%, but operational performance in real airport conditions diverges significantly. Operational accuracy is influenced by ambient lighting, physical weariness, headwear, age, and facial orientation. Research consistently demonstrates that facial recognition systems exhibit higher False Non-Match Rates for older travellers, individuals with disabilities, and individuals with darker skin tones. When a system fails to recognise a valid traveller, that individual is redirected to a secondary queue, turning the frictionless journey into an experience marked by additional delay and scrutiny.

When these failures concentrate along demographic lines, the system produces systematic, technology-mediated differential treatment that exposes operators to significant ethical and reputational risk.

Managing demographic equity requires airports to shift accountability back to technology providers and operational governance. Small hubs must require vendors during contract renewals to provide disaggregated accuracy data - specifically False Non-Match Rates broken down by age and skin tone using standardised scales like the Fitzpatrick scale - reflecting real-world operational deployments rather than laboratory benchmarks. Medium hubs should institute quarterly internal audits of match failure rates across all touchpoints, paired with qualitative assessments of fallback queues to ensure staff interactions remain efficient and respectful. Large hubs must commission independent, third-party demographic accuracy audits using test populations that reflect their actual passenger demographics prior to expanding biometric infrastructure, while contributing funding and data to help establish standardised industry-wide equity testing protocols.

Cybersecurity and avoiding vendor lock-in

The fourth theme covers cybersecurity, interoperability, and the risk of proprietary lock-in. A digital identity infrastructure connecting passport data, biometric markers, and travel histories across multiple entities represents one of the highest-value data targets in civilian infrastructure. A breach at this layer is uniquely dangerous because biometric templates cannot be reissued or cancelled like payment cards.

Centralised biometric databases present a single point of failure, whereas decentralised architectures - such as self-sovereign identity models where travellers hold verified credentials on their personal devices - distribute risk much more securely. Concurrently, commercial implementations often deviate from open standards, creating closed vendor ecosystems that lock airports into proprietary stacks. Operators that build on closed systems face exorbitant transition costs later when trying to integrate new airlines or upgrade technologies.

Protecting systems against cyber threats and vendor lock-in requires deliberate architectural choices across all hub tiers. Small hubs must verify that every operating biometric vendor maintains current SOC 2 Type II certification, defined breach notification windows, and contractual guarantees ensuring biometric templates use open standards that allow full data portability upon contract termination.

Medium hubs must execute annual tabletop exercises simulating identity-layer data breaches to test notification protocols, legal compliance, and operational fallbacks, while formally evaluating the financial risk of proprietary vendor dependencies. Large hubs must actively architect their identity ecosystems around open standards like ICAO’s Digital Travel Credential and W3C Verifiable Credentials, prioritising decentralised self-sovereign models and modular software architectures that allow individual software components or hardware touchpoints to be replaced without rebuilding the entire system.

The decisions that will define airport identity

The window between now and 2029 will irrevocably shape the future of airport identity infrastructure. The technical capability to process passengers seamlessly across international boundaries is already proven, but technology alone cannot guarantee an equitable, secure, or privacy-preserving travel environment.

Airport leaders across all hub sizes must move beyond viewing biometric deployments as mere operational efficiency upgrades or vendor-led IT implementations. By taking immediate action to establish robust consent architectures, enforce strict data retention limits, monitor demographic accuracy, and demand open, interoperable security standards, airport executives can build a digital identity framework that earns public trust while delivering a truly modern passenger experience.

I will be co-chairing a VIP roundtable on biometric implementation at the upcoming International Airport Summit taking place in Rome on 10-12 November. I will be hosting the discussion on ‘One token to rule them all: digital identity and the frictionless airport journey’ and ‘Data, trust, and the passenger relationship: what are we actually asking people to accept?’ If you would like to join the exclusive, closed-door discussions then you can register your interest via the link below.

Register for the roundtable